CVE-2021-27857

HIGHCVSS 7.5/10EPSS 1.79%

Last modified

CVE-2021-27857 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly guess the hostname of the target system since the hostname is used as part of the configuration archive file name. EPSS estimates a 1.79% chance of exploitation in the next 30 days.

Description

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly guess the hostname of the target system since the hostname is used as part of the configuration archive file name. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA003.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
1.79%

75.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
FatpipeincIpvpn Firmware5.2.0R34
FatpipeincIpvpn Firmware6.1.2R70p26
FatpipeincIpvpn Firmware7.1.2R39
FatpipeincIpvpn Firmware9.1.2R129
FatpipeincIpvpn Firmware10.1.2R60p10
FatpipeincIpvpn Firmware10.2.2R10
FatpipeincMpvpn Firmware5.2.0R34
FatpipeincMpvpn Firmware6.1.2R70p26
FatpipeincMpvpn Firmware7.1.2R39
FatpipeincMpvpn Firmware9.1.2R129
FatpipeincMpvpn Firmware10.1.2R60p10
FatpipeincMpvpn Firmware10.2.2R10
FatpipeincWarp Firmware5.2.0R34
FatpipeincWarp Firmware6.1.2R70p26
FatpipeincWarp Firmware7.1.2R39
FatpipeincWarp Firmware9.1.2R129
FatpipeincWarp Firmware10.1.2R60p10
FatpipeincWarp Firmware10.2.2R10

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-27857?
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly guess the hostname of the target system since the hostname is used as part of the configuration archive file name. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA003.
How severe is CVE-2021-27857?
CVE-2021-27857 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.79% probability of exploitation in the next 30 days.
How do I fix CVE-2021-27857?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-27857?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST